PT-2026-98648 · Linux · Linux Kernel
CVE-2026-97984
·
Published
2026-09-25
·
Updated
2026-10-07
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.6.21
Description
An issue exists in the IPv6 implementation where a UDP length overflow can occur when using Path MTU (PMTU) discovery with an unusually large Maximum Transmission Unit (MTU). When the
setsockopt IPV6 MTU DISCOVER is configured as IPV6 PMTUDISC DO or IPV6 PMTUDISC PROBE, the system may allow the maxnonfragsize to be set to the device MTU instead of the maximum allowed IPv6 MTU. If a large packet is sent over a network device with an MTU exceeding the standard limit, the resulting UDP length can overflow the 16-bit length field, triggering a warning in the udp set len short() function. This occurs specifically within the ip6 append data() function when cork->base.fragsize is not properly bounded.Recommendations
Update the Linux kernel to a version where the
cork->base.fragsize is bounded to IP6 MAX MTU for UDP sockets.
As a temporary mitigation, avoid setting IPV6 MTU DISCOVER to IPV6 PMTUDISC DO or IPV6 PMTUDISC PROBE on network devices with an MTU larger than the standard IPv6 maximum.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel